Malicious PDF — malware analysis report

Static analysis result for SHA-256 c6fd4215293667e3…

MALICIOUS

PDF

80.7 KB Created: 2021-03-25 04:17:04 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: faaf1d9b4bb9dd576f44e194786c5a88 SHA-1: 61eed672241b79b31ff7fded0a2410f3ac5e00e1 SHA-256: c6fd4215293667e3c2767c1ee6b304774b2469ecf3a3528219bcf679ecddd221
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by multiple heuristics, including ClamAV and an ML classifier, indicating malicious content. It contains a large number of external links, with one prominent URL pointing to a suspicious domain ('druttle.ru') that is likely part of a link farm or phishing operation. The presence of embedded URLs and the PDF_SEO_LINK_FARM heuristic suggest an attempt to direct users to potentially harmful websites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://druttle.ru/wix?keyword=karuna+reiki+master+manual+pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/e7a59b69-b0eb-459f-bb90-1a05347a600c/how_to_fix_kitchenaid_superba_dishwasher_top_rack_adjuster.pdf
    • http://gowatane.rf.gd/bhojpuri_video_songs_2019_hd_mp4.pdf
    • https://d7ae471b-a447-437d-81b4-4e603f8679d9.filesusr.com/ugd/0a3240_780321fee90c46d8b32f0d1ee46fb4f2.pdf?index=true
    • https://6acf0ca1-aa41-4771-8b91-54baff69ee7f.filesusr.com/ugd/7d1dc9_375abcb5703649648c0054f0acf8d2fa.pdf?index=true
    • https://57eba762-b826-4879-8d7a-7f480aba2934.filesusr.com/ugd/e89c2b_9b22729fa5ea43a1b1b34e6eadef4873.pdf?index=true
    • https://uploads.strikinglycdn.com/files/83241c57-c8df-4685-96cf-2613fda966dc/government_budgeting_for_dummies.pdf
    • http://zerujafulo.rf.gd/5271712526.pdf
    • https://9c43cb74-45e3-47de-9527-fda2e8336169.filesusr.com/ugd/af0aa9_33c906d46d824e8eacb381f886096a85.pdf?index=true
    • https://51da6a7d-ee05-4a49-87ee-1b74af3aeb07.filesusr.com/ugd/b80405_4508d90f584740e08c5f89c82b373153.pdf?index=true
    • https://901c4554-6fda-40bf-8344-1f1538f5dc06.filesusr.com/ugd/a76634_6a49100e9dea4a96a7bb20ca52e2030e.pdf?index=true
    • https://2fe0a9f4-4d23-48c4-8711-d5fb25093877.filesusr.com/ugd/683a75_25a18f5c0a6647578571c9727b5083db.pdf?index=true
    • https://f64a1a0a-debf-4843-a838-a34c0cae0f4a.filesusr.com/ugd/89602e_a11e5e43e8ea40a0b95332e3660f39e1.pdf?index=true
    • https://48b7024d-7414-4593-b44d-ed892b96ad15.filesusr.com/ugd/3e5db3_a300ebd1d47441f6a2b2f0b7dcbbb4f3.pdf?index=true
    • https://7fe1f042-206b-4735-a408-f56337efeeb4.filesusr.com/ugd/d34b51_f31880b65c1044a59f9554864dcf0784.pdf?index=true
    • http://damikofem.rf.gd/axis_and_allies_1940_pacific_rules.pdf
    • http://juvisupejigu.epizy.com/vozixijesusojaxixabal.pdf
    • https://e22e8d81-f41f-4d51-abb1-39b19d2d32bb.filesusr.com/ugd/96bf9d_0b28c42517ec47f98c9a7ff0c8b52161.pdf?index=true
    • https://uploads.strikinglycdn.com/files/347eb7ae-6fae-45dc-a608-167bc8cc4447/36763586050.pdf
    • https://57eba762-b826-4879-8d7a-7f480aba2934.filesusr.com/ugd/e89c2b_6eaae3ff86164271b823addae7c40302.pdf?index=true
    • https://aa4c2489-c93b-4667-afab-104bf5323bad.filesusr.com/ugd/8b49c6_8027f0341b9848d2b4852858390e63af.pdf?index=true
    • https://b3a1a1c9-4f8f-4fb8-b7cc-7339030cc889.filesusr.com/ugd/162fe6_cb6248086f154b13ae3fb24028904218.pdf?index=true
    • https://6ec3981f-6443-463b-a164-91fc69f101d9.filesusr.com/ugd/7603ae_e67606125ddc46ccbe62828f9595d355.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000fcf9.bin
467466768639a0d1ec498205a389cd826fd8a50e9df1690c2422825f657600a2
pdf-font-stream PDF embedded font (sfnt) at offset 0xFCF9 5220 bytes
font_01_sfnt_off00010ea8.bin
ca34b2ea3f55b340b50f07127e19c48b0ef843e7ef01aa03b4e1f7314e286ce2
pdf-font-stream PDF embedded font (sfnt) at offset 0x10EA8 11024 bytes